Note “Do not read the next line as it’s meant for Search Engines”.
WordPress got updated to 5.4.1 on 29th April 2020 and is avialble for download.
This security and maintenance release features 17 bug fixes in addition to 7 security fixes. Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 3.7 have also been updated.
WordPress 5.4.1 is a short-cycle security and maintenance release. The next major release will be version 5.5.
You can download WordPress 5.4.1 by downloading from WordPress.org, or visit your Dashboard → Updates and click Update Now.
If you have sites that support automatic background updates, they’ve already started the update process.
Seven security issues affect WordPress versions 5.4 and earlier. If you haven’t yet updated to 5.4, all WordPress versions since 3.7 have also been updated to fix the following security issues:
Wordpress Development India can help you secure your wordpress website by providing you maintenance services that includes secruity audit of your entire website along with database.
Props to Muaz Bin Abdus Sattar and Jannes who both independently reported an issue where password reset tokens were not properly invalidated
Props to ka1n4t for finding an issue where certain private posts can be viewed unauthenticated
Props to Evan Ricafort for discovering an XSS issue in the Customizer
Props to Ben Bidner from the WordPress Security Team who discovered an XSS issue in the search block
Props to Nick Daugherty from WordPress VIP / WordPress Security Team who discovered an XSS issue in wp-object-cache
Props to Ronnie Goodrich (Kahoots) and Jason Medeiros who independently reported an XSS issue in file uploads.
Props to Weston Ruter for fixing a stored XSS vulnerability in the WordPress customizer.
Additionally, an authenticated XSS issue in the block editor was discovered by Nguyen The Duc (ducnt) in WordPress 5.4 RC1 and RC2. It was fixed in 5.4 RC5. We wanted to be sure to give credit and thank them for all of their work in making WordPress more secure.
Thank you to all of the reporters for privately disclosing the vulnerabilities. This gave the security team time to fix the vulnerabilities before WordPress sites could be attacked.
For more information, browse the full list of changes on Trac, or check out the version 5.4.1 HelpHub documentation page.
For details visit
WordPress Development Company In India keeps you updated with the latest WordPress updates and features.
If you are looking for WordPress Maintenance Services in India feel free to contact me to get the most affordable packages.